Binance Tests Employees With Fake Phishing Attacks
Binance runs monthly internal phishing simulations on staff through its red team. Chief security officer Jimmy Su says repeated failures affect performance reviews and could lead to dismissal.
Binance is running monthly simulated phishing attacks on its own employees and tying the results directly to performance reviews, chief security officer Jimmy Su has confirmed.
How the Program Works
Binance runs an internal security system that carries out simulated phishing attacks on employees every month and can dismiss staff who repeatedly fail. The simulated attacks are handled by Binance's internal ethical hacking group, the red team, which infiltrates systems to find vulnerabilities and designs fake attack scenarios targeting employees.
Scenarios range from fake recruitment pitches to bogus conference invitations and attempts to collect personal data. The red team rotates tactics to keep tests realistic and broad. Su said the program has been in place for three to four years, and security awareness, which was lacking at first, has since improved substantially across the company.
Stakes for Employees
Su told Cointelegraph that Binance's internal red team performs phishing simulations on a monthly basis, and employees who fail receive remediation training, while continued poor performance can affect their performance review ratings and, in extreme cases, lead to dismissal.
Su said employees are incentivised to perform well because the results are reflected in their performance reviews. "If someone repeatedly fails the phishing-simulation attack, that will negatively impact their rating. That's the incentive to be vigilant." Repeated, severe failures could lead to their rating bottoming out, which could see them dismissed.
Binance says it has been running internal, simulated phishing attacks against its own staff for several years, testing how well employees resist social engineering attempts and tying repeat failures to remediation training and performance consequences. Social engineering continues to be a major driver of crypto security incidents.
Sources
Cointelegraph: Binance red team runs monthly phishing tests on employees
Crypto News: Binance red teams its own staff every month to keep hackers out
Latest News
Read More...
Author
Soumen DattaSoumen has been a crypto researcher since 2020 and holds a master’s in Physics. His writing and research has been published by publications such as CryptoSlate and DailyCoin, as well as BSCN. His areas of focus include Bitcoin, DeFi, and high-potential altcoins like Ethereum, Solana, XRP, and Chainlink. He combines analytical depth with journalistic clarity to deliver insights for both newcomers and seasoned crypto readers.













